The package includes a clear license, consumer documentation, repository tests, and release notes for this version. Its small dependency set and matching source repository help, but security documentation is absent.
55%
Total Score
50
100
93
75
The package has 7 releases but none in the last 12 months, and the latest release was in November 2019. This is a substantial maintenance concern despite the package not being deprecated.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the release history showing no release activity since November 2019. This raises abandonment risk.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a secondary concern because the package otherwise has a linked, matching source repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phoole/base Version ^1.0.20 | — | — |
psr/http-message Version ^1.0 | — | — |
psr/http-server-middleware Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.